Back to skill

Security audit

Monad Development

Security checks for vulnerabilities and agentic risk

Overview

This Monad development skill is mostly purpose-aligned, but it directs agents to persist raw wallet private keys and send contract source/build metadata to a third-party API without enough user control or safeguards.

Review this skill carefully before installing. It may be useful for Monad development, but do not let it create or store a wallet private key unless you explicitly choose a secure storage method, and avoid using it with any funded or mainnet wallet by default. Before contract verification, confirm what source code and metadata will be uploaded and whether agents.devnads.com is an acceptable intermediary for your project.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:55
Finding

Mandatory Disclosure of Contract Source and Build Metadata to a Third-Party Verification API

Content
View full analysis
\ --chain 10143 \ --show-standard-json-input > /tmp/standard-input.json cat out/.sol/.json | jq '.metadata' > /tmp/metadata.json COMPILER_VERSION=$(jq -r '.metadata | fromjson | .compiler.version' out/.sol/.json) # 2. Call verification API STANDARD_INPUT=$(cat /tmp/standard-input.json) FOUNDRY_METADATA=$(cat /tmp/metadata.json) cat > /tmp/verify.json << EOF { "chainId": 10143, "contractAddress": "0xYOUR_CONTRACT_ADDRESS", "contractName": "src/MyContract.sol:MyContract", "compilerVersion": "v${COMPILER_VERSION}", "standardJsonInput": $STANDARD_INPUT, "foundryMetadata": $FOUNDRY_METADATA } EOF curl -X POST https://agents.devnads.com/v1/verify \ -H "Content-Type: application/json" \ -d @/tmp/verify.json ``` ### Technical Analysis The Skill instructs the agent to submit the complete Solidity standard JSON compiler input and Foundry metadata to `agents.devnads.com`. Standard JSON input can contain the complete source tree, imported source files, compiler settings, and other project details. Foundry metadata can additionally disclose build and source-reference information. Although contract verification inherently involves publishing verification material, routing it through this third-party aggregation API is not the least-privileged option. The same Skill documents direct Sourcify verification as a fallback, demonstrating that disclosure to this intermediary is not technically mandatory. The workflow does not require user consent, show the exact payload before transmission, inspect source files for embedded credentials, or document the receiving service's retention and privacy properties. It also writes the complete payload t ...[truncated 1478 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:11
Finding

Untrusted Mutable Remote Documentation Can Hijack Agent Instructions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:99
Finding

Mandatory Plaintext Wallet Private-Key Persistence and Potential Chat Disclosure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instructions explicitly tell the agent to save and disclose wallet private key material in plain language, including telling the user where credentials are stored. Even if framed as convenience, this normalizes unsafe handling of high-value secrets and can lead to irreversible fund loss if the key is exposed or retained in an insecure location.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

Faucet (Testnet Funding):

bash
curl -X POST https://agents.devnads.com/v1/faucet \
  -H "Content-Type: application/json" \
  -d '{"chainId": 10143, "address": "0xYOUR_ADDRESS"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

The verification API transmits contract metadata and full standard JSON compiler input to a third-party endpoint. While this is often necessary for source verification, it may disclose unpublished source code, build settings, paths, and metadata before the user explicitly approves public disclosure or understands the trust boundary.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

} EOF

curl -X POST https://agents.devnads.com/v1/verify
-H "Content-Type: application/json"
-d @/tmp/verify.json

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs agents to persist generated wallet private keys to local files or .env files without requiring strong user consent, encryption, or an explicit warning about theft risk. Persisting raw blockchain credentials on disk materially increases the chance of compromise through logs, backups, shell history, misconfigured permissions, or accidental source control exposure.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
96% confidence
Finding

The skill mandates session persistence of newly generated wallet credentials for future use. Persisting authentication material across sessions increases the blast radius of compromise and creates durable secret artifacts that may be accessed by other processes, users, backups, or future prompts.

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
**CRITICAL for agents:** If you generate a wallet for the user, you MUST persist it for future use.

When generating a new wallet:
1. Create wallet: `cast wallet new`
2. **Immediately save** the address and private key to a secure location
3. Inform the user where the wallet details are stored
4. Fund the wallet via faucet before deployment

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
4. Fund the wallet via faucet before deployment

**Storage options:**
- Write to `~/.monad-wallet` with chmod 600
- Store in a project-specific `.env` file (add to .gitignore)
- Return credentials to user and ask them to save securely

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

At L168-L169, the documentation explicitly states that --no-commit is not a valid flag for forge init or forge install. However, the ERC20 example at L252-L255 tells the user to run forge install OpenZeppelin/openzeppelin-contracts --no-commit, which directly contradicts the earlier guidance.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This example again sends full contract verification data, including compiler input and constructor arguments, to an external API. In a smart-contract workflow this can expose proprietary source or sensitive deployment details earlier than intended, making the risk real though context-dependent.

Content

Scanner excerpt · SKILL.md (reported line 288)May include surrounding context.

md
STANDARD_INPUT=$(forge verify-contract <TOKEN_ADDRESS> src/MyToken.sol:MyToken --chain 10143 --show-standard-json-input)
COMPILER_VERSION=$(jq -r '.metadata | fromjson | .compiler.version' out/MyToken.sol/MyToken.json)

curl -X POST https://agents.devnads.com/v1/verify \
  -H "Content-Type: application/json" \
  -d "{
    \"chainId\": 10143,

Static analysis

No suspicious patterns detected.